MAL-2026-10755

    Dashboard / Malicious Package / MAL-2026-10755

    MAL-2026-10755

    Published: 16 Jul 2026Last Modified: 28 Jul 2026

    Summary: Malicious code in captcha-solve-api (PyPI)

    Details: Source: amazon-inspector (99621af0900df34246c87811ea5c2a643f2b3805601136dcc0a6768e48af925f) The PyPI package captcha-solve-api contains no captcha functionality and is instead a binary dropper disguised as an analytics SDK. A custom setuptools install class copies telemetry.pth into site-packages, and site.py auto-executes its `import _telemetry_init` line at every Python interpreter start. `_telemetry_init._bootstrap()` spawns a daemon thread that runs `_telemetry_transport.Client.initialize()`, which selects a per-OS/arch asset path (`/pkg/package`, `/pkg/package-arm64`, `/pkg/loader_mac`, `/pkg/package.exe`) from rotating Cloudflare Worker hosts (package-proxy.cf5oobworker.workers.dev, package-proxy.cf8oobworker.workers.dev, package-proxy.cf12oobworker.workers.dev, package-proxy.cf17-ddb.workers.dev, package-proxy.cf25-6eb.workers.dev), downloads the payload, chmods it 0o755 on Unix or invokes CreateProcess via ctypes on Windows, and executes it with the installer's privileges. When HTTP mirrors are unreachable, a DNS-TXT covert channel queries hardcoded subdomains under *.dl.well1.site (tin/tina/ldr/win.dl.well1.site) via public resolvers 8.8.8.8 and 1.1.1.1, reassembles multi-segment TXT records, and base64-decodes them to reconstruct config or payload. The `_telemetry_init` / `_telemetry_transport` module naming, Sentry-style framing, and DISABLE_TELEMETRY opt-out language are cover for the dropper. Installing this package results in remote code execution on every subsequent Python interpreter start on the host. Source: kam193 (6745bff1a72b44a9e53129210993aa7a3d0b95e8d9a0a2b2cdfe91324a8e8477) Package presents little functionality, but excessive fake 'telemetry' module. This fake telemetry is used to download and run malicious executables. Code is designed to survive different blocks: first, there is an attempt to download the executable from one of five Cloudflare Workers. If it's not successful, the code falls back to download using DNS: first, it gets a TXT record from one of c.*.dl.well1[.]site domains, depending on the system. This record returns a number, which is then used to iterate over domains in the form <0...n>.*.dl.well1[.]site and reconstruct the encoded executable from their TXT records. The downloaded binary is then executed and removed afterward. Using a PTH file ensures persistence and runs on every Python start. In this campaign, versions 0.0.1 hold disarmed code (without the necessary configuration), which is completed in further updates. This is a continuation of the 2026-07-haproxy-config-client campaign. Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-07-andreiiiiiii_i Reasons (based on the campaign): - The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk. - The package overrides the install command in setup.py to execute malicious code during installation. - Downloads and executes a remote executable. - covering-tracks - persistence - abuses-pth - data-stored-in-dns

    Affected packages

    Package

    Name: captcha-solve-api

    Purl: pkg:pypi/captcha-solve-api

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    0.0.1
    MAL-2026-10755 | CVE-DB